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Abstract 

Formalising mathematics in dependent type theory often requires to represent sets as setoids, 
i.e. types with an explicit equality relation. This paper surveys some possible definitions of 
setoids and assesses their suitability as a basis for developing mathematics. According to 
whether the equality relation is required to be reflexive or not we have total or partial setoid, 
respectively. There is only one definition of total setoid, but four different definitions of partial 
setoid, depending on four different notions of setoid function. We prove that one approach 
to partial setoids in unsuitable, and that the other approaches can be divided in two classes 
of equivalence. One class contains definitions of partial setoids that are equivalent to total 
setoids; the other class contains an inherently different definition, that has been useful in the 
modeling of type systems. We also provide some elements of discussion on the merits of each 
approach from the viewpoint of formalizing mathematics. In particular, we exhibit a difficulty 
with the common definition of subsetoids in the partial setoid approach. 



1 Introduction 

Proof-development systems such as Agda (Coquand & Coquand, 1999), Coq (2002) 
and Lego (Luo & Pollack, 1992) rely on powerful type systems and have been 
successfully used in the formalization of mathematics. Nevertheless, their underlying 
type theories - Martin-Lof's Type Theory (Nordstrom et ai, 1990) and the Calculus 
of Inductive Constructions (Werner, 1994) - fail to support extensional concepts 
such as quotients and subsets, which play a fundamental role in mathematics. While 
significant efforts have been devoted to embed subset and quotient types in type 
theory (Altenkirch, 1999; Barthe, 1995a; Courtieu, 2001 ; Hofmann, 1994; Hofmann, 
1995b; Hofmann, 1995a; Jacobs, 1999; Maietti, 1999; Salvesen & Smith, 1988), all 
proposals to date are unsatisfactory, mostly because they introduce non-canonical 
elements or lead to undecidable type-checking. Thus current versions of Agda, 
Coq and Lego do not implement subset or quotient types. Instead, mathematical 
formalizations usually rely on setoids, i.e. mathematical structures packaging a 
carrier: the "set", its equality: the "book equality" and a proof component ensuring 
that the book equality is well-behaved. This notion was introduced in constructive 
mathematics by Bishop (1967). 
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While setoids have been extensively used in the formalization of mathematics, 
there does not seem to be any consensus on their precise definition. Instead, setoids 
come in several flavours: for example, they can be total (the book equality is an 
equivalence relation) or partial (the book equality is a partial equivalence relation); 
classical (apartness is defined as the logical negation of equality) or constructive 
(setoids come equipped with an apartness relation independent from the equality 
relation). Worse, literature about setoids fails to compare the respective merits of 
existing approaches, especially from the viewpoint of formalising mathematics. 

The purpose of this paper is four-fold: 

• in section 2, we review existing approaches to define (the category of) setoids. 
It turns out that there are several alternatives to define morphisms of partial 
setoids, leading to different definitions of the category of partial setoids; 

• in section 3, we show that there are, up to equivalence of categories, two 
approaches to setoids. Further, we show that one approach to partial setoids, 
that appears in the literature, uses a definition of function setoid that does not 
give a correct exponent object for a cartesian closed category; 

• in section 4, we assess the suitability of the different approaches by considering 
choice principles. We show that both partial and total setoids can be turned 
into a model of intuitionistic set theory by assuming the axiom of unique 
choice. However, the axiom of unique choice for partial setoids is too weak, 
in that it does not permit us to define some very natural functions on partial 
setoids ; 

• in section 5, we introduce some basic constructions on setoids, such as subsets 
and quotients, and assess the relative advantages of existing approaches w.r.t. 
these constructions. 

Setting and notations To fix ideas, we shall be working with an extension of the 
Calculus of Constructions with dependent record types and universes. Dependent 
record types are used to formalize mathematical structures and universes are used to 
form the type of categories. Note that we do not need record subtyping and cumu- 
lativity between universes and that equality between records is neither extensional 
nor typed. However, our results are to a large extent independent from the choice 
of a type system. 

Following Luo (1994), we use Prop for the universe of propositions, Type, for the 
i-th universe of types. By abuse of notation, we write Type for Type 0 so we have 
Prop:Type and Type, : Type i+1 . Moreover, we use the notation (I : L, r : R) for a 
record type with two fields I of type L and r of type R and (I = a, r = b) for an 
inhabitant of that type. Finally, we let = denote Leibniz equality, defined as 

XA : Type.Ax, y : A. UP : A -> Prop. (P x) -> (P y) 

Proof scripts Most of the results presented in the paper have been formalized in 
the proof assistant Coq V7.3 and can be obtained from the following web page: 
http : // www-sop . inria . f r/lemme/Venanzio . Capretta/setoids/ index . html. 
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2 Setoids 

This section gathers some existing definitions of setoids. Here we focus on classical 
setoids, i.e. setoids that do not carry an apartness relation. Similarly, we ignore issues 
related to the decidability of equality and do not require equality to be decidable. In 
this setting, there is a single reasonable definition for total setoids and morphisms 
of total setoids. Also, there is a single reasonable definition for partial setoids, but 
there are at least four possible definitions for morphisms of partial setoids. 

Below we give these possible definitions of setoids. None of them is original. The 
first definition has been used, for example, in the formalization of basic algebra 
(Aczel, 1993; Barthe, 1995b) and of constructive category theory (Huet & Sai'bi, 
2000). The second definition has been used, for instance, in the formalization of 
polynomials (Bailey, 1993). The other definitions have been used by Hofmann (1994, 
1995a, 1995b) to interpret extensional concepts in intensional type theory. 

2.1 Total setoids 

A total setoid consists of a type T (the carrier), a binary relation R on T (the book 
equality), and a proof that R is an equivalence relation over T. 

Definition 1 

The type of total setoids is defined as the record type 

SET t = (el ( : Type, eq t : el t — > e\ t —> Prop, er : Er e\ t eq t ) 

where 

Er = aA : Type./ti? : A — * A — ► Prop. 

( refl t : Vx : A. R x x, 

sym f : Vx,y : A. (R x y) — > (R y x), 
trans f : Vx,y,z : A. (R x y) — > {R y z) — > (R x z)) 

By abuse of notation, we write el t A for A ■ e\ t and = A for A ■ eq t . 

Each type T induces a setoid $ T defined as 

(elt = T, eq T = Xx,y : T. x = y, er = . . .) 

A map of total setoids is a map between the underlying carriers which preserves 
equality. So, if A and B are two total setoids, a map of total setoids from A to B 
consists of a function / : el t A — ► el t B and a proof that / preserves equality. 

Definition 2 

Let A and B be two total setoids. 

• The type MAP t A B of morphisms of total setoids from A to B is defined as the 
record type 

MAP f A B = ( ap( : el ( A —> e\ t B, 

exi t ■ Vx,y : el ( A. (x = A y) -> (ap t x = B ap f y)) 

By abuse of notation, we write ap ( / a for / • ap t a. 
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• The function space setoid Map £ A B of maps from A to B is defined as the 
record 

MAP f A B = { el f = MAP f A B, 

eq r = kf,g :map ( A B. Vx : el t A. (ap t / x) = B (ap t g x), 
er = ...) 

We conclude this paragraph by observing that it would have been equivalent to 
define equality between morphisms from A to B as 

A/,g : map ( A B. Vx,y : e\ t A. (x = A y) -> (ap t / x) = B (ap t g y) 

This alternative definition will be used later for partial setoids, but in that case the 
two definitions will not be equivalent. 

2.2 Partial setoids 

A partial setoid consists of a type T (the carrier), a binary relation R on T (the 
book equality) and a proof that R is a partial equivalence relation over T. 

Definition 3 

The type of partial setoids is defined as the record type 

Set p = (el p : Type, eq p : el p ->■ el p ->■ Prop, per : Per el p eq p ) 

where 

Per = }.A : Type.A.R : A ->• A -» Prop. 

( sym p : \lx,y : A. (R x y) ^ (R y x), 
trains^ : Vx,y,z : A. (R x y) — > (R y z) — > {R x z)) 

By abuse of notation, we write el p A for A ■ el p and = A for A ■ eq p . 

In the framework of partial setoids, one distinguishes between defined and un- 
defined elements. The defined elements of a partial setoid A are those expressions 
x : elp A such that x = A x; they form the domain of the partial setoid. 

Definition 4 

• The domain of a partial setoid A is defined as the record type 

domain A = (cont : el p A, def : cont = A cont) 

• The domain setoid of a partial setoid A is defined as 

Domain A = ( el p = domain A, 

eq p = ax, y : domain A. x ■ cont = A y ■ cont, 
per = ...) 

Note that the underlying equality of domain setoids is a total equivalence relation. 
In the next section, we will use domain setoids to relate partial setoids to total setoids. 

We now turn to the definition of morphism of partial setoids. It turns out that there 
are several possible alternatives for this notion; below we present four alternatives 
that appear in the literature. The alternatives are determined by the following two 
issues: 
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1. What is the status of extensionality? Following the definition of morphism 
of total setoids, a morphism of partial setoids from A to B can be defined 
as a pair (/,</>/) where / is a type-theoretical function mapping "elements" 
of A to "elements" of B and </>/ is a proof that / preserves equality; this 
definition is similar to the one for total setoids. However, one can also take 
advantage of the possibility to restrict the defined elements by using a partial 
equivalence relation and choose (1) to define morphisms of setoids as type- 
theoretical functions, (2) to embed extensionality in the definition of equality 
for morphisms of setoids - in such a way that a morphism is defined w.r.t. the 
equality of the setoid Map A B iff it preserves equality. 

2. What is the domain of the function? A morphism of partial setoids from A to 
B may either take as inputs elements of A, or elements of Domain A - in the 
latter case, one will require that the morphism is constant in the def field of 
the record. 

This leaves us with four alternatives, which are summarized and described below. 



Extensionality vs. inputs 


Elements of A 


Elements of Domain A 


In the definition of morphism 


Set p 


Set, 


In the definition of equality 


Set,- 


Set, 



• The first alternative, which appears in Bailey (1993), is to adapt to partial setoids 
the definition of map of total setoids. Indeed, one can define a map of partial 
setoids as a map between the underlying carriers which preserves equality. 

Definition 5 

Let A and B be two partial setoids. 

• The type map,, A B of P -morphisms of partial setoids from A to B is defined 
as the record type 

MAPp A B = ( ap p : el p A — ► el p B, 

extp : Vx,y : e\ p A. (x = A y) -> (ap p x = B ap p y)) 

By abuse of notation, we write ap p f a for / • ap p a. 

• The P -function space setoid Map p A B of maps from A to B is defined as the 
record 

Map p A B = ( elp = MAPp A B, 

eq p = lf,g: map p A B. Vx : el p A. 

(x = 4 x) -» (ap p / x) = B (app g x), 
per = ...) 

Note that / =m AP( a b f f° r ever Y A, B : Set p and / : map p A B. 

• The second alternative requires that a function from A to B takes two arguments, 
namely an element a : e\ p A and a proof <j> : a = 4 a. The second argument is here 
to prevent some anomalies with empty sets (see section 3.2), but the result of the 
application of the function does not depend on it. 
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Definition 6 

Let A and B be two partial setoids. 

• The type map, A B of Q-morphisms of partial setoids from A to B is defined 
as the record type 

map, A B = { ap, : ria : el p A. (a = A a) — > el p B, 

ext, : Vx, y : el^ A!i<j) : x = A xM\p : y =a y. 
(x = A y) ->• (ap, x <p = B ap, y ip)) 

• The Q-function space setoid Map, A B of maps from A to B is defined as the 
record 

Map, A B = ( e\ p = map, A B, 

eq p = Xf,g: map, A B. Vx : el p A. V0 : (x =a x). 

(ap g f x<l>)= B (ap, g x 4>l 
per = ...) 

This approach makes function application awkward; perhaps for this reason it 
has never been used in practice. Note that / =]y[ A p a b f ^ or ever Y A, B : Set^ 
and / : map, A B. 

• The third alternative, which appears in Hofmann (1995b) and has been used 
extensively in Cubric et al. (1998) and Qiao (2000), does not require inhabitants 
of the carrier type of the function setoid to preserve equality : instead, the function 
space between A and B is defined as a partial setoid with carrier el^ A —* e\ p B. 
Equality is defined in the obvious way; as a consequence, the defined elements of 
this partial setoids are those type-theoretical functions preserving equality. 

Definition 7 

Let A and B be two partial setoids. 

• The type map,. A B of R-morphisms of partial setoids from A to B is defined 
as the type 

map,. A B = e\ p A — > elp B 

• The R-function space setoid Map,. A B of maps from A to B is defined as the 
record 

Map,. A B = ( el p = map,. A B, 

eq p = Xf,g : map,. A B. Vx,y : el p A. 

(x = A y) -> / x = B g y, 
per = ...) 

Note that we need not have / =jy[ A p A B f for A, B : Set,, and / : map,. A B : 
in other words, Map,. A B may be a partial setoid. Also, note that transitivity of 
equality for Map,. A B uses that 

Vx,x' : elp A. (x =a x') — ► x = 4 x 

which is provable from the symmetry and transitivity of = A . 

• The fourth alternative, which appears in Hofmann (1994), takes as inputs defined 
elements of A and does not require inhabitants of the carrier type of the function 
setoid to preserve equality. 
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Definition 8 

Let A and B be two partial setoids. 

• The type map s A B of S-morphisms of partial setoids from A to B is defined 
as the type 

map s A B = Yla : e\ p A. x =a x — > el p B 

• The S-function space setoid Map, A B of maps from A to B is defined as the 
record 

Map, A B = { e\ p = map, A B, 

eq p = Xf,g : map s A B. Vx,y : el p A. 
V<j) : x = A x. Vty : y = A y. 
(x = A y) ->• / x <f> = B g y w, 
per = ...) 

2.3 Total functional relations as movphisms? 

All previous definitions introduce morphisms of setoids as (structures with under- 
lying) type-theoretical functions. In contrast, set theory views morphisms of sets as 
graphs. One may therefore wonder about this departure from mainstream math- 
ematics. Two points need to be emphasized: 

• first, our type theory is expressive enough to formalize the notion of total 
functional relation and thus one needs not depart, at least in principle, from 
mainstream mathematics; 

• secondly, our type theory does make a difference between the two approaches : 
every function has an associated total functional relation but the converse 
needs not be true. 

In section 4 we provide some choice axioms under which the two approaches coincide, 
and briefly discuss the validity of our results/claims in other type-theoretical settings, 
but for the time being, let us focus on the relative benefits of the two approaches : 

• Using type-theoretical functions as the underlying concept for morphisms of 
setoids is very much in line with the philosophy of type theory because it 
provides a computational meaning to functions. In effect, most formalizations 
of mathematics in type theory follow the first approach. 

• Using total functional relations as the underlying concept for morphisms of 
setoids avoids some of the difficulties with choice principles, see Section 4. 
On the other hand, total functional relations do not have a computational 
meaning, which is a weakness from a type-theoretical perspective, and their use 
complicates the presentation of formal proofs, because it becomes impossible 
to write / a for the result of applying the function / to a. 

While we are strongly in favour of using type-theoretical functions as the the 
underlying concept for morphisms of setoids, we would like to conclude this section 
by observing that it is possible to use a monadic style to manipulate total functional 
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relations. Concretely, our suggestion is to use the (-monad 1 , which assigns to every 
setoid A : SET t the setoid r A defined as the predicates over A that are satisfied by 
exactly one element. Formally, we need to introduce the setoid Q of propositions, 
defined as 

(el t = Prop, eq f = XP,Q: Prop. P <-> Q, er = . . .) 
the quantifier 3 \ x G A. P x, where A is a total setoid, defined as 

3x : el f A. (P x) A (V> : e\ t A. P y x = A y) 

the type of predicates over A that are satisfied by exactly one element 

i A = (up : MAPf AO., pp : 3! x e A. ap t up x) 

and finally the setoid i A itself 

(elf = i A, eq r = XP, Q : i A. P ■ up = M ap, a a Q ' U P> er = • • ■> 

It is easy to turn ; into a monad. For example, the unit t], of the monad is defined 
as 

XA : SETf. ( ap f = Xx : el f A. ( up = (ap r = Xy : e\ t A. x = A y, ext t = ...), 

pp = ...), 

extf = . . .) 

To our knowledge, this approach has not been pursued before, and we have no 
practical experience with it; yet we feel that it is likely to be less cumbersome than 
manipulating total functional relations directly. 

We conclude this section by observing that it is possible to treat total relations 
likewise, i.e. by defining an e-monad which maps every setoid A to the setoid e A of 
non-empty predicates over A. Concretely he type of non-empty predicates over A is 
defined as 

eA = (np : map £ A Q, ne : 3x : el ( A. ap f np x) 
and the setoid e A is defined as 

(elf = eA, eq t = XP,Q:e A.P ■ np =m A p, a a Q ' n P' er = • • •) 
Again, it is a simple matter to turn e into a monad. 

3 Categories of setoids 

The purpose of this section is to associate to every notion of setoid its corresponding 
category, and show that all categories defined in the previous section form a model 
of the simply typed 1-calculus. However, it turns out that the function space setoid 
for PSet does not correspond to the exponent that turns PSet into a cartesian closed 
category. Further, we compare the five categories of setoids; it turns out that there 
are essentially two categories of setoids : TSet, which is equivalent to QSet and SSet, 
and RSet, which is equivalent to PSet. 

1 A monad in a category C is a triple (M,r\,n) where M:C — > C is a functor, ij:id([; — > M and 
ji:MoM-»Mate natural transformations such that \i o = ft o M\i and \i o r\M = fi o Mr\ — \&m- 
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3.1 The category of total setoids 

In this subsection, we define the category of total setoids and show that it forms a 
cartesian closed category. Following previous work on the formalization of category 
theory in type theory (Aczel, 1993; Huet & Safin, 2000; Sai'bi, 1998), a T-category 
(or simply a category) consists of 

• a type obj of objects (in TypeJ; 

• a polymorphic setoid of morphisms horn : obj — > obj — ► Set £ ; 

• a polymorphic composition operator 

• : Y\A,B,C : obj. bmap ( (horn A B) (horn B C) (horn A C), 

where BMAP t X Y Z is defined as MAP t X (Map ( Y Z); 

• a polymorphic identity id : IL4 : obj. el t (hom A A); 

• a proof that composition is associative and identity acts as a unit. 

Note that objects of a category are required to form a type, but the morphisms 
between two objects are required to form a setoid because we need to identify equal 
morphisms : Leibniz equality, which is the default equality relation in type theory, is 
too rigid for this purpose. 

Definition 9 

The type Cat £ of T-categories is defined as the record type 



(obj 


: Type!, 


hom 


: obj — > obj — > SET f , 


• 


: IL4, B,C : obj. BMAP t (hom A B) (hom B C) (hom A C), 


id 


: YIA : obj. hom A A, 


catlaw 


■ <£cat) 



where </> cat is 

(VA,B,C,D : obj. V/ : hom A B. Vg : horn B C. V/i : hom_ C D. 
f • (g • h) =(hom A D) (f • g) • h) 
A (VA,B : obj. V/ : hom_ A B. 

(id A)»f = (hom A B ) f A / • (id B) = (hom A B ) f) 

using hom Y Z as a shorthand for el; (hom Y Z) and x • y as a shorthand for 
ap £ (• x) y. In the sequel, we use obj c , hom c and hony as shorthand for C ■ obj, 
C ■ hom and el t (hom c Y Z) respectively. 

Total setoids can be made into a category that plays in CAT f the role that Set 
plays in standard category theory. 



Definition 10 

The category TSet of total setoids takes as objects elements of SET t and as homset 
between A and B the setoid Map £ A B. 
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obj c -> obj c ,, 

Tlo,o' : obj c . MAP t (hom c o d) (home (fobj o) (fobj o')), 



Functors are denned in a similar way; informally, a functor from C : CAT t to 
C" : CAT t consists of 

• a function fobj : obj c — > ob] c , ; 

• a polymorphic map of setoids 

fmor : Ilo, d : obj c . MAP t (hom c o d) (home (fobj o) (fobj o')); 

• a proof that fobj preserves identities and composition. 
Definition 11 

The parametric type FuNC t of T -functors is defined as 

AC, C : CAT f . ( fobj 
fmor 
flaw 

The parametric type BFuNC t of T-bifunctors is defined as 

1C,C',C" : CAT f . ( bfobj : obj c obj c , -> obje, 

bfmor : Ylo,o' : obj c . IIw, u f : obje- 

BMAP t (home o o') (home « «') 

(home (bfobj o u) (bfobj d u')), 

bflaw : ...) 

We now proceed towards the definition of cartesian closedness and define the 
notions of terminal object, products and exponents. Recall that o is a terminal 
object if for every object d there exists a unique morphism from d to o. 

Definition 12 

The parametric type TOBj t of terminal objects is defined as: 



kC : CAT t . ( fobj 
tarr 
flaw 



obj c , 

no : obj c . hom c o fobj, 

Vo : obj c . V/ : hom c o tobj. / = (homc Q tobj) tarr o) 

As appears from the above definition, terminal objects are understood constructively. 
This constructive reading of categorical notions is in line, for example, with Huet & 
Sai'bi (2000) and Sa'ibi (1998), and is more appropriate for the issues tackled here. 

Definition 13 

The parametric (record) type PROD f is defined as 

AC : CAT t . ( prodo : obj c — > obj c — ► obj c , 

proda : Ilo, d , o" : obj c . bmaP; (hom c o d) (hom c o o") 

(hom c o (prodo d o")), 
prodl : Ilo, d : obj c . hom c (prodo o d) o, 
prodr : IIo,o' : obj c . hom c (prodo o d) d, 
prodlaw : • • •) 

Given a category ^ with a product structure prod : PROD t ^, we use the notation 
o x d for prod • prodo o d . We also use the notation / x /' : horn* o\ x o\ o 2 x d 2 
to denote the product morphism of / : horn* oi o 2 and /' : horn* o\ o' 2 . 
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We can now define a Cartesian Closed Category (CCC) as a structure consisting 
of: 

• a category 1g ; 

• a terminal object •; 

• a bifunctor for products x : <6 x <€ — > ( €; 

• a bifunctor for exponents => : ^ op x <€ — * # ; 

• an evaluation map eval 0>() < : hom ((o => d) x o) d for every pair of objects o 
and d; 

• an abstraction map abst 0>0 < i0 » : MAP f (hom (o x d) o") (hom o {d => o")) for 
every three objects o, d , and o" ; 

• a proof that for every / : hom (o x d) o", ap ( abst 0/ / >0 » / is the unique 
morphism that gives back / when composed with eval 0 < >0 ». 

Definition 14 

The type of cartesian closed categories CCQ is the record type 

(cccat : CAT t , 
terminal : TOBj r cccat, 
ccprod : Prod £ cccat, 

ccexp : cccat • obj — > cccat • obj -> cccat • obj, 
cceval : Ilo, d : cccat • obj. cccat • hom ((o ^> d) x o) d , 
ccabst : Ilo, d,o" : cccat • obj. 

MAP t (cccat • hom (o x d) o") (ccat • hom o (d => o")), 
cceq : Vo, d, o" : cccat • obj.V/ : cccat ■ hom (o x d) o". 

((ap; ccabst (V / j0 » /) x (cccat • id d)) • cceval ( y i0 » 

= (cccathom (oxo') o") f> 

ccunique : Vo,o',o" : cccat • obj. 

V/ : cccat • hom (o x d) o".Vg : cccat • hom o (d => o"). 

(g X (cccat • id d)) • CCeval oV ,« =(cccat hom (oxo') o") f 
* S = (cccat hom o (o'=>o")) ap f CCabst 0 ( y 0 » /) 

where we use the notations oxo' for (cccprod-prodo o d) and o => d for (ccexp o d) 
and we write the object parameters as indexes, for example we write cceval ( / 0 « for 
(cceval d o"). 

Note that this is a constructive definition of cartesian closed category : a cartesian 
closed category is a category with extra structure. So what does it mean for a category 
of setoids to be a cartesian closed category? The following definition provides two 
possible answers to the question. 

Definition 15 

• A category C : CAT f is a cartesian closed category if there is a <€ : CCQ such 
that <e ■ cccat = C. 

• A pair (C,E) with C : CAT t , E . C ■ obj — » C ■ obj — * C ■ obj is a canonical 
cartesian closed category if there is a <<? : CCQ such that # • cccat = C and 
# • ccexp = E. 
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We use the terminology "canonical cartesian closed category" to specify that 
exponents are given canonically by an exponent function, and not just required to 
exist. Clearly C is a cartesian closed category iff (C,£) is a canonical cartesian closed 
category for some exponent function E. 

Lemma 16 

(TSet, XA, B : SET t . MAP t A B) is a canonical cartesian closed category. 

3.2 The categories of partial setoids 

We now turn to categories of partial setoids. Their definition is similar to that 
of TSet, but rely on a different formalism. Indeed, we have seen in the previous 
subsection that setoids and morphisms of setoids must come before and be the 
base of category theory. Consequently, we will have different notions of category 
according to the notion of setoid and setoid morphism we assume. More precisely, 
we will have four versions of category theory that we call P-category theory, Q- 
category theory, R-category theory and S-category theory; and inside each of these 
settings we can define the categories PSet, QSet, RSet and SSet, respectively. These 
categories will play a similar role as the one played by the category Set in standard 
category theory. 

Definition 17 

Let X range over P, Q, R and S. The type Cat x of X-categories is defined as the 
record type 

(obj : Type l5 

horn : obj — > obj — > Set x , 

• : YIA,B,C : obj. bmap x (hom A B) (hom B C) (hom A C), 

id : IL4 : obj. el x (hom A A), 

catlaw : 0 cat ) 

where (/> ca i is suitably defined. 

Other notions, and in particular the notion of cartesian closed category can be 
adapted likewise. 

Definition 18 

• The P-category PSet takes as objects elements of Set p and as homset between 
A and B the setoid Map p A B. 

• The Q-category Qset takes as objects elements of Set p and as homset between 
A and B the setoid Map, A B. 

• The R-category RSet takes as objects elements of Set p and as homset between 
A and B the setoid Map,. A B. 

• The S-category SSet takes as objects elements of Set p and as homset between 
A and B the setoid Map., A B. 

In the following lemma, we are interested in determining whether the categories 
PSet, QSet, RSet and SSet with their associated function space setoid, as defined in 
the previous section, form canonical cartesian closed categories. 
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Lemma 19 

The following pairs are canonical cartesian closed categories: 

• (PSet, Li, B : Set p . Map,. A B) 

• (QSet, Li, B : Set p . Map,, A B) 

• (RSet, 14,5 : Set p . Map,. A B) 

• (SSet, kA,B : Set,,. Map., A B) 

It is interesting to note that (PSet, Li, B : Set,,. Map p A B) is not a canonical 
cartesian closed category. This can be established by exploiting anomalies related to 
"empty" partial setoids. 

Definition 20 

For any type T, the empty partial setoid 0 T over T is defined by 

0 T = { e\ p = T, 

eq p = kx,y : T. _L, 

per = ( sym p = kx,y : T. k p : _L. p, 

transp = kx,y : T. k p, q : _L. p)) 

Now let A = 0 Unit and let \ p = (el p = Unit, eq p = kx,y : Unit. T, per = •••). 
The type map p A (Map,, l p A) is empty: indeed, let / : map p A (Map p l p A). Then 
((/ • ap p *) • ext p * * !) : _L, where * is the only inhabitant of Unit and ! is the only 
proof of T ; this is impossible by consistency of the system. On the other hand, if 
there was a cartesian closed category of the form 

(cccat = PSet, ccexp = kA,B : Set p . Map p A B, ...} 

then the type map p A (Map p 1 p A) would be inhabited, a contradiction. On the basis 
of this observation, it does not seem adequate to formalize mathematics in type 
theory using partial setoids and the function space setoid Map p . 

3.3 Equivalence between categories 

The purpose of this paragraph is to establish whether the categories defined in the 
previous section are equivalent 2 . The basic conclusion, summarized in Table 1, is 
that there are, up to equivalences, two cartesian closed categories of setoids: TSet, 
equivalent to QSet and SSet, and RSet, equivalent to PSet. The * in the comparison 
of RSet and PSet means that the isomorphism does not preserve function setoids. 

Before proceeding any further, we would like to clarify what we mean by comparing 
categories. Formally, the standard notion of equivalence can only be used to compare 
categories that live in the same formalism. In particular, a standard definition of 
equivalence would not be appropriate to compare categories that do not belong 

2 An equivalence between two categories and 3 is a tuple (F, G, r\, e) where 

• F is a functor from <€ to 3; 

• G is a functor from 3 to c €; 

• ;j is a natural isomorphism from id ¥ to G o F; 

• e is a natural isomorphism from F o G to id^. 
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Table 1. Comparisons between categories {EQ = equivalence ; NOEQ = not 
equivalence; ISO = isomorphism) 





TSet 


PSet 


QSet 


RSet 


SSet 


TSet 




NOEQ 


EQ 


NOEQ 


EQ 


PSet 


NOEQ 




NOEQ 


ISO* 


NOEQ 


QSet 


EQ 


NOEQ 




NOEQ 


ISO 


RSet 


NOEQ 


ISO* 


NOEQ 




NOEQ 


SSet 


EQ 


NOEQ 


ISO 


NOEQ 





to the same framework, e.g. TSet which is a T-category and RSet which is an 
ft-category. One remedy to this problem is to define transformations that map 
categories in one formalism to categories in another formalism. Going back to 
TSet and RSet, one can for example transform TSet into an ^-category TSet r and 
compare it to RSet. Here we prefer to remain at an informal level of discussion, 
since our main purpose is to stress that not all existing alternatives are equivalent. 

3.3.1 Comparing TSet and RSet 
We begin by showing that TSet and RSet are not equivalent. 

Theorem 21 

The categories TSet and RSet are not equivalent. 
Proof 

Call an object o a weak initial (respectively, initial) object if for every object d 
there is at most one (respectively, exactly one) morphism from o to o\ Equivalence 
of categories preserves weak initial and initial objects, hence the following two 
observations are sufficient to conclude that TSet and RSet are not equivalent: 

• In RSet, there is a weak initial object that is not initial. 

• In TSet, every weak initial object is initial. 

For the first observation, take 0 Unit. Since this partial setoid does not have any 
defined element, all functions from it to any other setoid are equal, so it is an weak 
initial object. On the other hand, there is no morphism from 0 Unit to 0 Empty, 
because the underlying type function should have type Unit — ► Empty and there is 
no such function. 

For the second observation, let o be a weakly initial object in TSet. We prove that 
its carrier type must be the empty type. It is immediate to prove that if the carrier 
type of a total setoid is empty then the setoid is initial. From the fact that o is weakly 
initial it follows that the two constant functions c true , c fa | Se : MAP t o ($Bool), where 
Bool is the type with two elements true and false, must be equal. It immediately 
follows that the carrier of o is empty. □ 
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Nevertheless, there are two obvious functors PTPA : TSet — > RSet and 0t2T : 
RSet — > TSet. The functor PTPA is defined in the obvious way: its object part 
forgets the reflexivity of equality, and its arrow part forgets the extensionality of the 
morphism. As for PkPT , it is defined below. 

Definition 22 

The functor PAPT : RSet — ► TSet is defined as follows : 

• Object part: if A is a partial setoid, then Total A is its corresponding total 
setoid : 

Total A = { e\ t = domain (Partial A) 

= (cont : el t A, def : cont = A cont), 
eq t = ••• 
er = •••) 

• Arrow part: if g is a defined morphism of partial setoids from A to B, i.e. 
g : map,. A B and <f> : g =]yr AP A B g then PkPT g is defined as the record 

PAST g = ( ap f = /be : domain A. ( cont = g x ■ cont, 

def = <f> x ■ cont x • cont x ■ def) 
ext t = /be, y : domain A(/> x • cont y ■ cont) 

One can show that the obvious functors between TSet and RSet cannot give an 
equivalence, e.g. we can prove that PkPT is not full as in Lemma 31. 

3.3.2 Comparing TSet and QSet 

There are two obvious functors 2T2, : TSet ->■ QSet and 2.2T : QSet ->■ TSet. They 
form an equivalence pair. 

Definition 23 

The functor PTH : TSet — > QSet is defined as follows: 

• Object part : if A is a total setoid, then ST PI A = Partial A is its corresponding 
partial setoid (just forget the proof of reflexivity) : 



Partial A = 



(el p = 

eq P = 
per = 



el t (Total A) = domain B, 
•••> 
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• Arrow part: let A and B be total setoids and / : maP( A B. Then 2T 2 f : 
MAP q (2T 2 A) (2T 2 B) is defined by the components 

(2T2 f ) ■ ap q : Yla : el p {.T 2 A), a = (:ri A) a -> el p {.T 2 B) 

: Wa : e\ t A.a = A a — > el t B 
{ST 2 f ) ■ ap q = Xa : el t A. X (j> : a = A a. ap f / a 

(£T2f)-ext q : ~ix,y : e\ p (3~2 A). 

V0 : x = {:T1 A) xNxp : y = {srsi A) y. x = ( , rj A) y 
(ap q {ST 2 f) x <t>) = ( . ri B) (ap q {,T2 /) y rp) 
: "ix,y : el f AM<f> : x = A xM\p : y = A y x = A y 
-+ (ap f / x) = B (ap f / y) 
{ST 2 f) ■ ext q = Ax,y : e\ p (2T 2 A). X§ : x = A x. lip : y = A y. 
f ■ ext t x y 

The functor 22T : QSet — > TSet is defined as follows: 



• Object part : if A is a partial setoid, then 22T A = Total A is its corresponding 
total setoid. 

• Arrow part: let A and B be partial setoids and / : map^ A B. Then 2.T f : 
MAP t (2.T A) (2.T B) is defined by the components 

f) ■ ap t : el r {22T A) ->• el t {22T B) 

\ DOMAIN A — > DOMAIN B 

{22T f) ■ ap t = Xx : domain A.{ cont = ap 9 / x ■ cont x ■ def, 

def = / • extq x ■ cont x ■ cont 

x ■ def x ■ def x ■ def) 



{23T f) ■ ext t : Vx, y : el f {22T A).(x = (J , r A) y) 

^ ap t {.T2f)x = (r3 B] ap t {.T 2 f) y 
: Vx,y : domain A.x ■ cont = A y ■ cont — ► 

(ap^ / x ■ cont x ■ def) = B (ap q f y ■ cont y ■ def) 
{22T f) ■ ext; = Xx,y : domain A.f ■ exl q x ■ cont y ■ cont x ■ def y ■ def 

To show, that these functors form an equivalence we look at their two compositions 
and show that they are naturally isomorphic to the identity functor in the respective 
categories. 

Theorem 24 

The categories TSet and QSet are equivalent. 
Proof 

We shall define {&~2, 22T,Y\,e) is an equivalence between the categories. 
Let A : TSet, then we have 



2ST (ZT2 A) : TSet 

= Total (Partial A) 
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Let B : QSet, then we have 

ST 2, {2.ZT B) : QSet 

= Partial (Total B) 

The unit of the equivalence is then defined, for every A : TSet as the morphism 

n A ■ MAP r A (3,.T (,T J A)) 

n A = ( ap t : el t A -> el f (J^ (,TJ 4)) 

: el; ^4 — * (cont : el t A, def : cont =^ cont) 
= /be : el t A(cont = x,def : ^4 • er • refl ( x), 
ext; = • • •) 

n is a natural isomorphism between the identity functor Jjset and the functor 

The counit of the equivalence is defined, for every B : QSet as the morphism 
e B : map, {PSL (JiT B)) B 

e B = ( ap q : Ilx : el p {ST 3. {3.ST B)).x = ( , rj (J , r B)) x ^ p e\„ B 
: fix : domain B.x = { , r i (i,r b)) * -> p el p B 
= Ax : domain B.X(j> : x =(srn (nsr b)) x.x ■ cont, 
ext, = • • •) 

€ is a natural isomorphism between the functor 2T 3, o 3,T and the identity functor 

•/QSet- □ 

3.3.3 Comparing TSet and SSet 

The categories TSet and SSet are equivalent. The shortest way to show this fact 
is to prove that SSet is equivalent to QSet, and then we obtain the equivalence 
to TSet by Theorem 24. There are two obvious functors 3Ef : QSet — » SSet and 
if 3. : SSet — ► QSet. They are simply the identity on objects. On morphisms, 2,£f just 
forgets the proof component ext q , while £f H on the defined elements of Map., A B, 
that is the functions / : map., A B for which there is a proof £ : / =Map a b /> * s 

^<2/£ = <ap,=/,ext, = £> 

J,S^ and are inverse of each other, so 

Theorem 25 

The categories SSet and QSet are isomorphic. The categories SSet and TSet are 
equivalent. 

3. 3 A Comparing PSet and RSet 

We proved in Lemma 19 that PSet cannot be completed to a cartesian closed 
category having Map p A B as exponent object. Therefore there are no equivalences 
between PSet and any of the other four categories that preserves the setoid of 
functions. However, there is an equivalence between PSet and RSet that does not 
preserve the setoid of functions. 
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Definition 26 

The functor 001 : PSet -> RSet is denned as follows: 

• Object part: the identity. 

• Arrow part: if / is a morphism of partial setoids from A to B in PSet, i.e. 
/ : MAPp A B, then 00 f is simply / • ap p . 

The functor 00 : RSet -> PSet is defined as follows: 

• Object part: the identity. 

• Arrow part: if / is a morphism of partial setoids from A to B in PSet, i.e. 
/ : map,. A B such that / =]y[ A p A B f, then 00 f is the record 

00 f = {ap p = f,ext p = 0 

where £ is a proof that / is a defined element of Map,. A B, i.e. £ : 

(/ =Map,. iB/) = fe J : el f> 4 - (* =-4 y) -» (ap P / *) =b (ap P / y)- 

It is trivial to verify that and 00 with the identity natural transformations 
form an equivalence, actually even an isomorphism, between PSet and RSet. 

Theorem 27 

The categories PSet and RSet are isomorphic. 

3.3.5 Comparing TSet and PSet 

That TSet and PSet are not equivalent follows from the equivalence of PSet to RSet, 
Theorem 27, and the fact that TSet is not equivalent to RSet, Theorem 21. There 
are, however, two obvious functors 0~0> : TSet -> PSet and 0>3~ : PSet -> TSet. As 
expected, neither 0~ 0 nor SP.T yields an equivalence of categories. 

The functor 9~0 : TSet — > PSet is defined in the obvious way: its object part 
turns a total setoid into a partial setoid simply by forgetting about the reflexivity of 
equality, whereas its arrow part is the "identity". 

Definition 28 

The functor 0~ 0 : TSet — > PSet is defined as follows : 

• Object part: if A is a total setoid, then 

0-0 a = Partial A = { e\ p = A - el ( , 
eq p = A ■ eq t , 
per = ...) 

is its corresponding partial setoid. 

• Arrow part : the arrow part of 9~0 is the "identity". 

9~0 cannot induce any equivalence between TSet and PSet, as shown by the 
following lemma. 

Lemma 29 

There exists a partial setoid A : Set p that is not isomorphic to the image of any 
total setoid under 0~0. 
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Proof 

We exhibit a partial setoid A : Set p such that for every B : SET f , it must be that 
either Map p A {ST SP B) or Map p {9~ & B) A is empty. Indeed, assume V t : T and 
let ^4 = 0 T. Now assume B : Set s . We claim that in the empty context: 

• Map p {2T 3? B) A is not empty iff B is empty. Indeed, if b : el t B and 
/ : map,, (2T 0> B) A then / • ext p b b (B ■ er • refl t b) : _L, which is impossible 
by consistency of the system. 

• Map p A {9~ 2P B) is not empty iff B is not empty. 

The result follows. □ 

The functor SP.T mapping partial setoids to total setoids takes as object part the 
function mapping a partial setoid to its domain setoid, and as function part the 
corresponding transformation described below. 

Definition 30 

The functor 2P9~ : PSet — ► TSet is defined as follows : 

• Object part : if A is a partial setoid, then 

apg- A = total A = 
( el ( = domain A, 
eq t = Ax, y : domain A. x ■ cont =a y ■ cont, 
er = ( refl r = Ax : domain A. x ■ def, 

sym r = Ax, y : domain A. A ■ per • syrrip x ■ cont y ■ cont, 
trans r = Ax, y, z : domain A. 

A ■ per • tranSp x ■ cont y ■ cont z • cont)) 

is its corresponding total setoid — Domain A differs from Total A by the name 
of its fields. 

• Arrow part : if g is a morphism of partial setoids from A to B, i.e. g : map p A B 
then 3P9~ g is defined as the record 

3P2T g = ( ap; = Ax : domain A. 

{ cont = ap p g x ■ cont, 

def = g • extp x ■ cont x ■ cont x ■ def), 
ext t = Ax, y : domain A. g ■ ext p x ■ cont y cont) 

cannot induce any equivalence between TSet and PSet, as shown by the 
following lemma. 

Lemma 31 

The functor is not full, i.e. there exist two partial setoids A and B such that 
MAPp A B is empty but MAP t {3P2T A) B) is not. 

Proof 

Assume h t : T and let A = 0 T and B = 0 (domain A). We claim that in the empty 
context: 

• there is no g : map p A B. If there were such a g, then (ap p g t) ■ def : _L This 
is impossible by consistency of the system; 
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• there is a g : map £ (Total A) (Total B). Indeed, consider 

g = ( ap r = Xx : domain A. (cont = x, def = x ■ def ), 
ext f = Ax, y : domain A. kp : _L p) 

The expression g is indeed of type MAP t (Total A) (Total B) since we have 

el ( (Total A) =g domain A 
el t (Total B) =p domain (domain A) 
(x = (ToxAL A) y) =/j -L 
(aPt x = ( Total b) a Pf 3>) =P 1 

□ 

3.4 Discussion 

We have seen that there are up to equivalence two possible choices for a category of 
setoids, namely TSet and RSet. In the coming sections, we compare these approaches 
from the point of view of formalizing mathematics. 

One could also compare these categories from other perspectives, e.g. one could 
check which of the categories TSet and RSet do form a model of dependent type 
theory. This issue has been investigated in depth by Hofmann (Hofmann, 1995b). 
It turns out that the category RSet does form a model of dependent type theory, 
whereas there are some difficulties with TSet. In particular, it is problematic to 
define a family of setoids depending on a setoid. One could also check which of 
the categories TSet and RSet do form a model of intuitionistic set theory, i.e. a 
topos (Lambek & Scott, 1986). It turns out that none of the categories forms a 
topos because of the distinction between total functional relations and functions. In 
Section 4, we study choice principles which turn these categories into toposes. 

4 Choice principles 

To pursue the analysis of setoids as a type-theoretic formalization of the notion 
of set, we study their behaviour in relation to two choice principles: the axiom of 
choice and the axiom of description, also called axiom of unique choice. 

Before proceeding any further, we dispose of a possible criticism regarding the 
relevance of this enquiry : one may argue that the use of axioms, and in particular 
choice axioms, inside the theory of setoids is methodologically unjustified. In fact, 
setoids where devised to develop mathematics in type theory without external 
assumptions; if we are to assume axioms, we may as well assume all the axioms of 
set theory and dispense with setoids. While we agree that one should try to develop 
mathematics using only the constructions available in type theory, we still defend the 
importance of knowing the relation of the notion of setoid with choice principles, 
because this relation tells us much about the nature of setoids. Besides, as we will 
show, some seemingly natural choice principles are inconsistent in RSet. While one 
may not be interested in adding choice axioms, the fact that some choice principles 
are provably false is undesirable. 
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We consider the full axiom of choice and the axiom of descriptions, or unique 
choice - the former leads to classical logic, whereas the second is constructively 
valid. The axiom of descriptions is consistent in TSet, while in RSet there are two 
versions of it, the stronger one is inconsistent and the weaker one is too weak in 
that some very natural functions cannot be defined in it. Our conclusion is that TSet 
behaves better than RSet with respect to choice principles. 

4.1 The axiom of choice for types 

The axiom of choice for types expresses that every total relation from U to V yields 
a type-theoretic function of type U — ► V. 

Definition 32 

Let U and V be two types. The type tr U V of total relations from U to V is 
defined as the record type 

tr U V = ( rel : U -> V -+ Prop, 

total : Vx : U3y : V. rel x y) 

The axiom of choice for types is given by the context T^^j 
ACT make : YiU, V : Type, (tr U V) —> U —> V, 

ACT check : VI/, V : Type. VR : tr U V. Vx : U. R ■ rel x (ACJ make U V R x) 
The following result is well-known (Coquand, 1990; Werner, 1997). 

Proposition 33 

^ACT i s consistent, but not inhabited in the Calculus of Inductive Constructions. 



4.2 The axiom of choice for total setoids 

The axiom of choice for total setoids states that every total relation between total 
setoids induces a map of total setoids. A relation from A to B, where A and B are 
total setoids, consists of a type-theoretical relation R : (el t A) — > (el t B) — » Prop and 
a proof that R is compatible. 

Definition 34 

Let A and B be two total setoids. The type Rel, A B of relations from A to B is 
defined as the record type 

REL, A B = ( rel t : el ( A — * e\ t B — ► Prop, 

compat, : Vx,x' : el f A. Vy,y' : el f B. 

x =4 x' -> y = B y' -> rel t x y -> rel f x' /} 

An alternative definition of binary relations can be given as setoid functions with 
result in Q, with Q, defined as in section 2.3. A total relation from A to B is a relation 
R such that for every a : el< A, there exists b : el f B satisfying R ■ rel f a b. 
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Definition 35 

Let A and B be two total setoids. The type TREL t A B of total relations from A to 
B is denned as the record type 

TREL t A B = ( trel t : REL f A B, 

total t : Vx : el f A. 3y : e\ t B. trel f • rel f x y) 

The axiom of choice for total setoids is given by the context T^c 



The following result is well-known. 

Lemma 36 

The context Tj^q : 

1. is consistent; 

2. is not instantiable in the context T/±q j ; 

3. entails that TSet is a topos 3 with Q as subobject classifier; 

4. entails excluded middle, i.e. VA : Prop. A V -*A; 

5. entails proof-irrelevance, i.e. \IA : Prop.Vx, y : A. x = y. 

Proof sketch 

The first statement is derivable from the fact that the axiom of choice for setoids 
holds in the proof-irrelevance model - see also Hofmann (1995b); the second 
statement is derivable from the fourth and the non-provability of classical logic in 
the context T^ct- The third item states that TSet is a topos with Q as subobject 
classifier and is proved by a simple calculation. The fourth item states the provability 
of classical logic from the axiom of choice for setoids and follows from Diaconescu's 
construction, e.g. see Lacas & Werner (1999) and Lambek & Scott (1986). The 
last item establishes that proof-irrelevance, i.e. the property that all proofs of 
a proposition are equal (the property was first considered by de Bruijn in the 
Automath project (Nederpelt et al., 1994)), is derivable from the axiom of choice for 
setoids and can be established from Barbanera & Berardi (1996). □ 

We conclude this section by mentioning principles that are equivalent to the 
axiom of choice for setoids. It is well-known that the axiom of choice is equivalent 
to stating that every surjective function has a right-inverse. It is routine to define a 
context equivalent to Tj^q that constructs for every surjective function / from A to 
B a function g from B to A and a proof that g is right-inverse to A. One can also 
give a formulation of the axiom of choice that makes use of the e-monad defined 
in subsection 2.3; in this form the axiom states that we can exhibit an element of 
every non-empty predicate. The interested reader is referred to Capretta (2002). 

3 Informally, a topos 2T is a cartesian closed category with a subobject classifier, i.e. with an object that 
acts as a set of truth values, e.g. see Lambek & Scott (1986) for a precise definition. 




TIA,B : SeT(. (TREL t A B) —> (map, A B), 
VA,B : SeT(. V.R : TREL f A B. Vx : el t A. 
R ■ trel t • rel f x (ap t (AC make A B R) x) 
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4.3 The axiom of descriptions for total setoids 

As seen above, the axiom of choice for setoids is extremely powerful. A weaker form 
of choice principle, acceptable intuitionistically, is the axiom of descriptions, a.k.a. 
the axiom of unique choice, which states that every total functional relation induces 
a map. 

4.3.1 The axiom and its consistency 

A total functional relation from A to B, where A and B are total setoids, consists of 
a relation R on A and B and proofs that R is total and functional. 

Definition 37 

Let A and B be two total setoids. The type tfrel, A B of total functional relations 
from A to B is defined as the record type 

TFREL t A B = ( tfrel t : REL t A B, 

ttotal t : Vx : el t A. 3y : e\ t B. tfrel t • rel f x y, 
fun t : Vx : el t A. Vy,/ : el t B. 

(tfrelt • rel £ x y) -> (tfrel t • re\ t x y') -> y = B y') 

The axiom of descriptions for total setoids is given by the context r^rj 

AD ma ke '■ H4, B \ SET t . (TFREL t A B) — » (MAPj A B), 

AD check : VA,B : SeTj. VR : TFREL t A B.Vx : e\, A. 

R ■ tf rel r • rel t x (ap t (AD M t f A B R) x) 

The following result is well known. 

Lemma 38 

The context : 

1. is instantiable in the context T^^j; 

2. is consistent; 

3. entails that TSet is a topos; 

4. does not entail classical logic nor proof-irrelevance. 
Proof sketch 

The first item is proved by easy logical manipulations. The second item follows 
immediately from the consistency of r^CT- The third item is proved by simple 
calculations. The last item follows from the fact that classical logic and proof- 
irrelevance are not derivable from T^cr;. □ 

As with the axiom of choice, we can express the axiom of descriptions by stating 
that every bijection (i.e. injective and surjective function) has an inverse, but also in 
terms of the /-monad. Again, the interested reader is referred to Capretta (2002). 

4.4 Choice principles for partial setoids 

In this section, we focus on the axiom of descriptions for partial setoids. In fact, 
there are two possible formulations of the axiom, depending on the notion of total 
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relation one adopts. It turns out that one formulation is inconsistent, and that the 
other is too weak. More precisely, we show that some very natural functions that 
can be defined on a total setoid with the axiom of descriptions cannot be defined in 
the corresponding partial setoid, even in presence of (the second formulation of) the 
axiom of descriptions. This observation leads us to the position that total setoids 
are better suited for the development of mathematics in type theory than partial 
setoids. Notice that in the following we will not use exponents for partial setoids, so 
our results hold both for PSet and RSet. 

As suggested above, we first need to decide about the notion of total relation. A 
total relation from a partial setoid A to a partial setoid B can be defined in two 
different ways: 

• (definedness-irrelevant) as a relation R such that for every a : e\ p A there exists 
b : e\ p B such that R a b; 

• (definedness-relevant) as a relation R such that for every a : e\ p A such that a 
is defined, i.e. a = A a, there exists b : e\ p B such that R a b and b = B b. 

Each definition yields its variant of the axiom of descriptions. 



4.4.1 Axiom of descriptions, definedness-relevant version 

In this section, we define the definedness-relevant version of the axiom of descriptions 
and show it is inconsistent. 

Definition 39 

Let A and B be two partial setoids. 

1. The type Rel p A B of relations from A to B is defined as the record type 

rel,, A B = ( relp : e\ p A — > e\ p B — > Prop, 

compatp : Vx,x' : el p A. Vy,/ : e\ p B. 

x =a x' —* y =b y' —* relp x y — ► rel p x' y') 

2. The type tfrel p A B of total functional relations from A to B is defined as 
the record type 

TFRELp A B = { tfrelp : Rel p A B, 

ttotalp : Vx : el p A. (x = A x) 

-> ly : elp B. (tfrelp • rel p x y A y = B y), 
furip : Vx : el p A. Vy,y' : el p B. 

(tfrelp • relp x y) —> (tfrelp • relp x y') 
-> x =4 x -»■ y = B y') 

The axiom of descriptions for partial setoids is given by the context T pj^ 

AD M t e : IL4, B : SETp. (tfrel p A B) — > (map p A B), 
ADcheck : V/4, B : SETp. VR : TFRELp A B. Vx : el p A. 

R ■ tfrelp • relp x (ap p (AD make A B R) x) 
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Lemma 40 

The context is inconsistent. 
Proof 

For every type A and partial setoid B, one can prove that the empty relation 
r : RELp (0 A) B yields a total functional relation r' : tfrel,, (0 A) B and by the 
axiom of descriptions, a map / : map p (0 A) B. Now take A to be inhabited. It 
follows that every e\ p B is inhabited, so every type B is inhabited. □ 

4.4.2 Axiom of descriptions, definedness-irrelevant version 

In this section, we adopt the definedness-irrelevant definition of total functional 
relations. 

Definition 41 

Let A and B be two partial setoids. The type tfrel p A B of total functional relations 
from A to B is defined as the record type 

TFRELp A B = ( tfrelp : Rel p A B, 

ttotalp : Vx : el p A. 3y : e\ p B. tfrelp • rel p x y, 
fun p : Vx : el p A. Vy,/ : el p B. 

(tfrel p • relp x y) — > (tfrelp • rel p x y') 

x = A x -»• y = B y') 

Then the context F^p) is defined exactly as in the previous paragraph. 
Lemma 42 

The context T j±£) * s instantiable in the context r^c-p, and hence consistent. Further, 
in context r^p> RSet does form a topos. 

However, we show that some very natural functions that can be defined on a 
total setoid with the axiom of descriptions cannot be defined in the corresponding 
partial setoid with the axiom of descriptions. We will construct a counterexample, 
i.e. a function that is definable on a total setoid but not on the corresponding partial 
setoid. 

The counterexample is given by a length function that computes the length of 
eventually null sequences of natural numbers (we use N to denote the type of natural 
numbers). We use the extensional equality on sequences: If g\,G2 '■ N — * N, then 
(ffi =ext gi) = (Vi : N.ffi i = (72 0- The total version of the setoid is 

ZSeQ; = ( el ( = (seq : N -> N, evz : 3m : N.Vi : N. i > m — > seq i = 0), 
eq f = ko\,G2 '■ elf-Ci ' seq = ext a 2 • seq, 
er t = •••) 

In the context r^pj we can define a function lengtHj : MAP t ZSeq £ N f that gives 
the length of the part of a sequence that is nonzero (we use N; to denote $ N, i.e. 
the setoid derived from N by taking Leibniz equality as book equality). 

In contrast, we claim that there cannot be a version of this function if we use 
partial setoids. First, we let N p = (el p = N, eq p = Xx,y : N. x = y, per = . . .) be the 
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partial setoid of natural numbers and we define the partial counterpart of ZSEQ t as 

ZSeq,, = ( e\ p = N — > N, 

eq p = lai,a 2 : N — >• N.3m : N.Vi : N. 

(i si m -> (cri i) = (a 2 i)) A (i > m — > (ffi i) = 0 A {a 2 i) = 0), 
per = •••) 

Of course we could define ZSeq p from ZSEQ f by simply forgetting the proof of 
refiexivity, but what we want to stress here is that the idea of using the book 
equality to restrict the domain, which is the main advantage of partial setoids, does 
not always work as desired. 

Now we claim that there cannot be a version of the length function for ZSeq p in 
context r^r> 

Proposition 43 

The existence of the function length p : (map p ZSeq p N p ) is not derivable in 
context r^j)- 

The remaining of the paragraph is devoted to a proof of the proposition. We 
proceed by defining a context T^p such that r^pj, T^p is consistent and in which 
one can prove the length function does not exist. The context F^p, which captures 
the continuity principle 4 , is defined as 

CP make : ((N^N)^N)^(N^N)-+N 
CPcheck ■ VT : (N — » N) — > N. Va, /? : N — > N. 

(Vi : N. (i sc CP make F a) -> p i = a i) -> F /? = F a 

Lemma 44 

The context r^p^Fcp is consistent. 
Proof 

The context is valid in the realizability model. □ 

Further, we show that in the context T^p it is contradictory to assume the 
existence of the length function. 

Proposition 45 

Tqp h -iBLENGTHp : (map p ZSeq^ N p ). Vff : (ZSeq p • e\ p ).(7 =2Seq a ~~* 
a (LENGTHp • appp OA 
Vi : N.i > (LENGTHp • appp a) — > a i = 0 

4 The continuity principle is a well-known principle in intuitionistic mathematics. In constructive re- 
cursion theory, it follows from the Kreisel-Lacombe-Shoenfield theorem (see Troelstra & van Dalen 
(1988) and Chapter 16 of Beeson (1985)). In type theory, the continuity principle is stated as follows: 
For every operator F : (N — > N) — > N and for every sequence a : N — > N, there exists a natural number 
m such that, for every other sequence fl : N — > N that is equal to i for indexes up to m, that is, 
(P i) = (a i) for i m, we have that F(fi) = F(a). Notice that the Continuity Principle is not provable 
in type theory, but it is a meta-result that holds for the operators definable in type theory. For our 
purpose, however, it is sufficient to know that the continuity principle is valid in the realizability model, 
in which the axiom of descriptions is also valid. 
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Proof 

If there were a function length p : map p ZSeq p N p , then length^, • ap p : (N — > N) — ► N 
would be an extension of length to all sequences. We can apply the Continuity 
Principle to the operator length p • ap p and the constantly zero sequence 0. Hence, 
there must exist a natural number m such that, for all f> : N -> N satisfying 
(Vi : N. (i m) — > (3 i = 0 ; = 0), we have (ap p length^ /? = ap p length p 0 = 0). 
Now consider the sequence y defined by 

{0 if i s£ m 
1 if i = m + 1 
0 if i > m + 1. 

The sequence y coincides with 0 on the first m elements, and thus, for the consequence 
of the continuity principle ap p length p y = 0. On the other hand, y becomes 
eventually zero only after the element m+1, so we should have ap p length p y = m+1. 
We reached a contradiction, so our assumption that length p could be constructed 
is confuted. □ 

Notice that the crux of the counterexample is that, in the total setoid ZSEQ f , the 
carrier type already contains information on when the sequence becomes eventually 
zero. We can use this information to define lengtHj. This information is not present 
in the domain of the partial setoid ZSeq p , making it impossible to define the function 

LENGTH p . 

5 Mathematical constructions with setoids 

In this section, we study the type-theoretical analogous of two basic set-theoretical 
constructions, namely subsets and quotients, using setoids as an implementation 
of the intuitive idea of sets. In particular, we will show that the partial setoid 
methodology runs into practical difficulties when dealing with subsetoids. More 
specifically, we will see that the canonical definition of subsetoid in RSet is too 
weak, in the sense that if we use this definition, some natural functions on subsetoids 
cannot be defined, while they are definable in the corresponding total subsetoid. 

5.1 Subsetoids 

Total setoids, as embodied by TSet, and partial setoids, as embodied in RSet, 
are based on two distinct ways of restricting the domain of a structure, that is, 
of defining subsetoids. In the first case, restriction is achieved by modifying the 
underlying carrier of the setoid, while in the second case, restriction is achieved by 
modifying the setoid's underlying equality relation. However, we will show that total 
setoids are unavoidable, in the sense that, even if we use partial setoids, we will be 
forced to restrict the carrier type of a setoid to obtain certain subsetoids. 

We begin by reviewing the definition of subsetoids in the context of total setoids. 
Intuitively a subsetoid is that part of a setoid whose elements satisfy a predicate. 
Predicates on setoids are defined as type-theoretic predicates on the carrier sets that 
are invariant for the setoid equality. 
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Definition 46 

Let A be a total setoid. Setoid predicates over A are the elements of the record type 

PRED f A = ( pf( : el ( A — > Prop, 

inv t : Vx,y : el f A. (x = A y) -> (pf t x ->• pf t y)) 

Note that an equivalent definition would be PRED r A = MAP t ^4 fi. In TSet the 
subsetoid of a setoid .4 defined by a predicate P : PRED f A is obtained by first 
restricting the carrier type, and then constructing the setoid over this carrier by 
projecting the equality of A on the first component. 

Definition 47 

Let A : SET t and P : pred £ A. The carrier of the subsetoid selected by P from A is 

subCarrier A P = (subel : el t A, insub : P • pf f subel) 

and the subsetoid is 

suBSETOiD f A P = ( el t = subCarrier A P, 

eq t = Xx,y : el f .(subel x) = A (subel y), 
er = ---> 

Sometimes (if the axiom of descriptions is not supposed to be true) it is necessary 
to use a constructively stronger notion of predicate and subsetoid: the carrier of 
the predicate has type el, A — > Type so that its proofs can be used to construct 
elements of types. The rest of the definition is in this case the same, except for the 
substitution of Type for Prop. For the examples given below we assume either that 
this constructive definition is used or that the axiom of description (equivalently, 
the axiom of choice for types) is assumed. 

On the other hand, when using partial setoids, we do not change the underlying 
type, but we modify the equality. Predicates over partial setoids are defined in the 
same way as predicates over total setoids. 

Definition 48 

Let A be a partial setoid. Setoid predicates over A are the elements of the record 
type 

pred p A = ( pf p : e\ p A — > Prop, 

invp : Vx,y : el p A. (x = A y) -> (pf p x -> pf p y)) 

The prepositional function pf p must be defined on the whole carrier type el p A, 
even on elements x for which x = A x is not true. 

Definition 49 

If A is a partial setoid and P : pred p A, then we define the subsetoid of A selected 
by P as 

subSetoid p A P = (el p = el p A, eq p = Ax, y : el p A.(P • pf p x) A x = A y, per = • • •) 

In the definition of eq p we do not require (P • pf p y) because it is derivable from 
(P • pf p x), x = A y, and P • inv p . 
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This definition has the nice property that an element of the carrier of the subsetoid 
is automatically an element of the carrier of the setoid. However, a serious drawback 
of this approach consists in the fact that a function defined on a subsetoid of A 
must be a type-theoretic function defined on the entire carrier type of A. In some 
cases, this cannot be done and the use of suBSETOiD t A P is unavoidable. A first 
example of the above is given by the length function in the example of eventually 
null sequences that we developed in Subsection 4.4. Indeed, one can define the setoid 
of sequences as Map,. ¥S p N p , define the predicate of being eventually zero and then 
form the subsetoid of eventually zero sequences. Using the results of the previous 
section, this gives us a first example of a function that cannot be defined using 
subsetoids a la partial setoid. 

Below we develop a second example based on the real numbers. Here the idea is 
to define a setoid of real numbers and then restrict the setoid to smaller systems, 
say, the rationals or the natural numbers, for example. Of course, one would hope 
that the number systems defined in this fashion enjoy the same properties and have 
the same definable functions as their more standard counterparts. It turns out that 
this is not possible in the framework of partial setoids. 

It is well known that in a constructive setting there are several possible im- 
plementations of real numbers (e.g. see Chirimar & Howe (1992), Ciaffaglione & 
Gianantonio (2000), Geuvers et al. (2001), Harrison (1998) and Jones (1993) for 
some works on the formalization of reals in type theory). Here we choose to define 
the setoid of real numbers R using Cauchy sequences. The total setoid is defined as 

R t = ( el t = (seq : N — ► Q,con : Cauchy seq), 
eq r = lr u r 2 : e\ t . n ■ seq = CO nv r 2 ■ seq, 
er = ---> 

where Q is the type of rational numbers, Cauchy is the the property of being a 
Cauchy sequence of rationals: 

Cauchy s = Vi : N. 3k : N. Vj'i,j 2 : N. j\ > k — > j 2 > k — > |(s j\) — (s j 2 )\ < 1/i 

and =conv is the equality on sequences of rational numbers that holds whenever two 
sequences are co-convergent: 

(si =conv s 2 ) = Vi : N. 3k : N. Vj : N. j > k -> |(si j) - (s 2 j)\ < 1/i 

The corresponding partial setoid is 

R p = ( el p = N -> Q, 

eq^ = hr\,r 2 : el t . (Cauchy n) A (Cauchy r 2 ) A (n • seq = con v r 2 • seq), 
er = ---> 

As emphasized above, it is convenient to consider smaller number systems, like the 
natural or rational numbers, as subsetoids of the real numbers — an alternative would 
be to consider implicit coercions, see e.g. (Sa'ibi, 1997) but this falls beyond the scope 
of this paper. We have a type Q of rational numbers, that is not a subsetoid of R. 
We are going to define the subset of real numbers corresponding to the rationals. 
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To this end we use the relation ~> between N — > Q and Q, such that s ~» q holds if 
s converges to q : 

s ~> 3 = Vi : N. 3/c : N. Vj : N. i > k -> |(s j) - <z| < 1/i 

We define the predicate isRationaL( : PRED f R f by (isRationaL( • pf f r) = 3q : 
Q. s • seq ^> q. The predicate isRational p : pred p 1R p is defined correspondingly. 
Now we want to define the subsetoid of the reals whose elements are the real 
numbers that satisfy isRATiONAL t . This is Q t = (suBSETOiD f ]R t isRationaLj) in TSet 
and Q p = (subSetoid p 1R p isRational p ) in RSet. The problem now arises if we want 
to define a function on these subsetoids that depends strongly upon the satisfaction 
of the condition. For example, consider the function Num that gives the numerator 
of the reduced fraction representing a rational number. 

In the framework of partial setoids, defining Num on Q p requires that we define 
it on the whole type N — > Q, without any information on convergence. This is 
impossible because we cannot constructively compute whether a sequence converges 
to a rational value and, in such case, to which one. Further, it is also impossible to 
define Num with the axiom of descriptions. On the other hand, if we work in the 
framework of total setoids and use the axiom of descriptions for total setoids, we 
can easily define such a function for Q f since we can extract from one of its elements 
r the proof insub r containing the rational value of r. 

5.2 Quotients 

Both when working with total and partial setoids, quotients can be realized by just 
substituting the setoid equality with a stronger equivalence relation — below we refer 
to the latter as the quotienting relation. In either case the quotienting relation must 
preserve the setoid equality : if two elements are equal according to the book equality, 
they must be equivalent w.r.t. the quotienting relation. However, when working with 
partial setoids, a problem arises: the quotienting relation may hold for elements 
that are not equal to themselves according to the setoid equality, i.e. that are not in 
the domain of the setoid. In this case, taking the equivalence relation as the book 
equality of the quotient would add elements to the domain, which is incorrect. A 
solution, proposed by Hofmann (1995a), is to take as book equality in the quotient 
setoid the restriction of the equivalence relation on the original setoid to the domain 
of the setoid. We briefly develop this point below. 

Recall that an equivalence relation R over a setoid A is an element of REL t A A 
that satisfies reflexivity, symmetry, and transitivity. Now assume that A is a total 
setoid and that R is such an equivalence relation with 4> R to witness that R is indeed 
an equivalence relation. For the sake of readability, we write x =r y as a shorthand 
for R ■ rel t x y. In TSet the quotient setoid A/R is defined as 

(el f = el f A, eq, = Xx,y : el f A. x = R y, er = (f> R ) 

But in the same situation in RSet, i.e. with A is a partial setoid, R a partial equivalence 
relation with <j> R to witness that R is indeed an partial equivalence relation - and 
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using x = R y as a shorthand for R ■ re\ p x y it would be wrong to define (A/R) as 

(el p = el p A, eq p = Xx, y : el p A x = R y, per = <p R ) 

because it may happen that x = R x holds when x = A x does not hold, so we are 
introducing new elements in the setoid. Instead, we must define first R' : kel p A A as 

(relp = Xx,y : e\ p A.x = A x A y = A y A x = R y, compat = • • •) 

and then define (A/R) as 

(elp = elp A, eq p = Xx, y : e\ p A. x = RI y, per = . . .) 

6 Conclusion 

Type-theoretical frameworks are used as a foundation for mathematics in several 
ongoing efforts to develop large libraries of formalized mathematics with proof- 
assistants such as Agda, Coq and Lego. It is therefore natural to study the relation- 
ship between type theory and the standard foundational framework for mathematics, 
i.e. set theory. Recently, several authors (Aczel, 1999; Werner, 1997) have undertaken 
a systematic comparison between set theory and intensional type theory (see also 
Aczel (1978, 1982, 1986) for earlier work). 

This paper studies a related issue, namely the use of set-theoretic notions in type 
theory. More precisely, we focused on the use of setoids in the formalization of 
mathematics. We analyzed the different approaches to setoids that can be found in 
the literature, compared them, and drew some conclusions in regard to their appro- 
priateness. Specifically, we showed that existing approaches can be classified into 
two equivalence classes: the first equivalence class contains total setoids, TSet, and 
some equivalent versions of partial setoids, QSet and SSet. The second equivalence 
class contains an essentially different way of using partial setoids, RSet, and PSet; 
for the latter, we have shown that a previously used approach to function space is 
inadequate and needs to be redefined as in RSet. 

In addition, we compared the two classes under the aspect of suitability for 
the formalization of mathematics. In particular, we showed that the partial setoid 
methodology runs into practical difficulties when dealing with subsetoids. 
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